feat: add whoami and doctor so a wrong identity stops being invisible - #9
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Git gives you no way to ask which rule matched. An
includeIfthat never fires produces no warning, no error, and exit status 0 — it silently falls through. So every wrong-identity failure presents to the user as nothing at all.What this adds
gitmeright whoami— the resolved identity for this repo, which rule matched, and the key in use. When nothing matches it says why, specifically:Exits non-zero on a miss, so it is scriptable.
gitmeright doctor— ten read-only checks, each with an actionable remedy: git version against the 2.36/2.13 floors, every profile resolved against a fixture repo, rules that can never match,IdentitiesOnlypresence, key existence and mode,~/.sshpermissions, duplicate or missing includes, and a global[user]that would silently shadow every profile.--onlineconnects to each host and reports which account actually answered — the check that catches the failure whereuser.emailis right but ssh authenticates as someone else.Testing
64 tests green, 15 new. A broken state is constructed per check, asserting
doctorflags precisely that one. Both commands are read-only and there are tests asserting they write nothing.One bug these tests caught during development:
doctorreported a mode-644 key as an "incomplete pair", becausessh-keygenrefuses to read a world-readable key. Permissions are now checked before readability so the message points at the real fault.